Deserialization of Untrusted Data in NukeViet - CVE-2026-61832
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in extension store management handlers when processing an unverified HTTP response body. A remote attacker can substitute the response body with a crafted PHP serialized payload to execute arbitrary code.
Exploitation requires a privileged administrator to perform a store action such as opening the store list, install, update, or detail, and requires the ability to intercept or alter outbound traffic to the store endpoint.